Logo for Binary Defense

Cybersecurity Threat Hunter - REMOTE

Role overview

Qualifications

  • Hands-on experience hunting for threat actor activity using EDR and/or SIEM platforms such as Microsoft Sentinel, Splunk, and CrowdStrike.
  • Ability to build and tune hunting and detection queries in platform-native query languages.
  • Excellent written and verbal communication skills.
  • Working knowledge of threat actor techniques, defense evasion, and the current threat landscape.

Responsibilities

  • Track emerging threat actor techniques from breaking research and assess their relevance to client environments.
  • Develop original research from observed malware and threat actor TTPs.
  • Build and tune client-facing threat hunts across customer EDR and SIEM platforms.
  • Serve as a technical point of contact for clients, communicating hunt findings and recommendations.

About the company

Binary Defense logo

Binary Defense

Cybersecurity

Founded in 2014 by the industry’s top cybersecurity experts, Binary Defense is on a mission to change the security industry for the better and help organizations defend against threats of all kinds. We believe that the best defense against cyber threats uses a human-driven, technology-assisted approach. We protect businesses of all sizes through our advanced cybersecurity solutions including Managed Detection and Response, Threat Hunting, Digital Risk Protection, Incident Response, Phishing Response, and Analysis on Demand. Binary Defense was spawned from the need for better monitoring and detection capabilities in companies. The founder of Binary Defense, David Kennedy, also founded TrustedSec which specializes in information security services including penetration testing. The cutting edge, white hat hackers noticed almost every organization with monitoring capabilities really struggled, especially when using an MSSP. Countless attacks went undetected, and breaches were missed which left companies wondering what to do. As a result, Binary Defense was first put into motion in July of 2012 with the development of our Managed Detection, Deception and Response software (Binary Defense Vision) based on profiling how attackers think. A number of years of development, marrying up attack intelligence with our extensive threat intelligence, has made our product the best consolidation of technologies in the industry to predict, prevent, detect, deceive and respond to attacks.

Company details

Company typeSME
IndustryCybersecurity
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Job Type
Full-time
Description


Binary Defense is seeking a Threat Hunter to join our Threat Hunting Team. This role is built for someone who can hit the ground running: tracking threat actor techniques as they break, turning that intelligence into original research, and building the hunts that surface those threats across client environments.


The Threat Hunter position requires an experienced, analytical person who understands the techniques threat actors use to compromise systems and evade detection. A successful candidate will study those techniques, translate them into hunting and detection logic across multiple SIEM and EDR platforms, and clearly communicate findings to clients. The work spans researching breaking threat intelligence, hands-on analysis, detection engineering, and written communication, in a client-facing environment.


Hunts are delivered across EDR and SIEM platforms including Microsoft Defender, Sentinel, Splunk, and CrowdStrike. Threat Hunters produce client deliverables each week, with opportunities to publish original research as blog posts and to present research at security conferences.


Responsibilities


· Track emerging threat actor techniques from breaking research, threat intelligence reporting, and firsthand observation, and assess their relevance to client environments.

· Develop original research from observed malware and threat actor TTPs, including extraction of indicators of compromise (IOCs) and detection opportunities.

· Build and tune client-facing threat hunts as queries across customer EDR and SIEM platforms 

· Serve as a technical point of contact for clients, clearly communicating hunt findings, methodology, and recommendations to improve their security posture.

· Perform static and dynamic malware analysis to understand malicious behavior, execution flow, and common evasion techniques.

· Analyze telemetry, logs, and alerts to identify suspicious behavior across Windows, Linux, and macOS.

· Work closely with Threat Hunters and SOC analysts to support investigations and deliver technical findings.

· Keep current on the latest threat actor techniques and cybersecurity developments relevant to defending client networks.

· Support and mentor less experienced team members as you grow in the role.

Requirements


· Hands-on experience hunting for threat actor activity using EDR and/or SIEM platforms such as Microsoft Sentinel, Splunk, and CrowdStrike.

· Ability to build and tune hunting and detection queries in platform-native query languages (for example KQL and SPL).

· Excellent written and verbal communication, with the ability to explain technical findings clearly to clients and teammates.

· Working knowledge of threat actor techniques, defense evasion, and the current threat landscape.

· Experience turning threat intelligence into deployable hunt and detection logic.

· Familiarity with malware analysis techniques and the ability to interpret and apply results.

· Network traffic analysis experience.

· Experience with Windows environments, with working familiarity across Linux and macOS.

· Strong research and technical analysis skills.

· Well-developed problem-solving and interpersonal skills, strong organizational skills, and acute attention to detail.

· Associate's degree (or 2 or more years hands-on experience) in Computer Science, Information Security, Incident Response, Forensics, or a related field.


Preferred


· Bachelor’s or master’s degree in computer science or Cybersecurity (or 4 or more years hands-on experience).

· 2 or more years of experience in threat hunting, detection engineering, incident response, or a SOC role.

· Experience analyzing or de-obfuscating scripts (PowerShell, VBA, JavaScript, .NET, and similar).

· Scripting or programming experience (for example Python, PowerShell, or Bash) to support analysis and internal tooling.

· Experience publishing original research through blog posts, public reporting, or conference talks.

· Malware reverse engineering experience, both static and dynamic.

· Digital forensics and incident response experience.

· Experience mentoring other analysts.


About Binary Defense


Binary Defense is a leading Managed Detection and Response (MDR) provider, trusted by hundreds of organizations to protect what matters most. Our team of SOC analysts, threat hunters, detection engineers, and threat researchers work around the clock to deliver proactive, risk-focused security outcomes. We bring the attacker's mindset to defense, helping clients detect threats earlier, respond faster, and continuously improve their security posture.


For more information, visit our website, check out our blog, or follow us on LinkedIn.


Binary Defense offers competitive medical, dental and vision coverage for employees and dependents, a 401k match which vests every payroll, a flexible and remote friendly work environment, as well as training opportunities to expand your skill set (to name a few!). If you’re interested in joining a growing team with great perks, we encourage you to apply!

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Binary Defense

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.